DIVELOGIQ / PRIVACY
Privacy
Last updated: 10 October 2026
1. Controller
Agentur Zentral GmbH, Gumbinnenstraße 6, 38112 Braunschweig, Germany. Represented by Marco Dittmer. Privacy contact: info@divelogiq.de, telephone +49 531 25 77 44 44.
2. Scope
This notice covers the DiveLogIQ information website and account area. The website provides product information, downloads, account creation and sign-in. Signed-in users can synchronise their logbook, certifications and personal map records between Android and Windows.
3. Hosting and technical logs
Hosting is provided by ALL-INKL.COM, Neue Medien Münnich. A visit transmits technical data including the IP address, time, requested address, browser and connection information. Depending on server configuration, access and error logs are created. The purposes are delivery, stability and security of the website (Article 6(1)(f) GDPR). We use technical logs only for error and security analysis. Details of the hosting provider’s specific retention periods are available on request. Longer retention may be needed to investigate a specific security incident.
4. Accounts and licence grants
For user accounts we store the email address, a secure password hash, account status, licence grants and technical timestamps. Processing provides the requested account and its use (Article 6(1)(b) GDPR). Account and licence data is retained to provide the account. Deletion requests are handled through the contact above, subject to statutory retention obligations.
5. Secure sign-in and sessions
Information pages set no cookies. Opening the account area sets the technically necessary DLIQSESSION session cookie for sign-in and protection against forged form requests. It applies only to the visited domain, cannot be read by JavaScript and is sent over HTTPS. Sign-in expires after 30 minutes of inactivity or at most eight hours. Signing out deletes the cookie. Storage serves only the requested account function (Section 25(2)(2) TDDDG).
6. App access and abuse prevention
Native access tokens are stored server-side only as hashes. Access tokens last one hour and renewable refresh tokens 30 days. After refresh expiry, token metadata is cleaned up at the next sign-in attempt. A signed offline licence contains the account ID, grants and expiry, but no password. Sign-in and registration requests are recorded to limit abuse. Failed sign-in attempts are stored with secret-keyed hashes of email/network identifiers and a timestamp. Entries older than 24 hours are removed at the next sign-in attempt. For registration attempts, we also keep a similarly hashed network identifier and timestamp for up to 24 hours, cleaned up on the next account request. This protects accounts against abuse (Article 6(1)(f) GDPR).
7. Logbook synchronisation
When a connected client uses synchronisation, we store submitted dives, equipment, profiles, field definitions and their recorded IQ context under that account. Device and operation identifiers, revisions and change history support safe retries and conflict detection. Deletions are distributed as tombstones; earlier contents remain in the change journal. Records and history remain until account deletion or a separately documented cleanup. Complete account deletion can be requested at info@divelogiq.de. The user-data export contains no passwords or access tokens. Protected administrative backups are accessible only for operations; a daily trigger creates encrypted backups, verifies restoration and retrieves a separate local copy. Fourteen successfully verified snapshots are retained at each location. The trigger requires an available operations computer; missed runs are not counted as successful backups.
8. Certifications and private originals
Authenticated accounts with the required entitlement can submit certification details and PDF, JPEG and PNG files through the wallet API. We store qualification details, optional notes, original files, filenames, checksums and technical upload progress to provide the requested storage, synchronisation and display (Article 6(1)(b) GDPR). Other accounts cannot retrieve these files. Incomplete transfers with no activity for seven days are removed during administrative cleanup. Completed originals and history remain available for restoration and synchronisation after a local deletion marker, until account deletion or documented cleanup. An export includes certification details and completed original files. No verification by the issuing association takes place.
9. Friendships and shared dives
Active accounts may choose a display name and send a friendship request using an exact account identifier. The sign-in email is not published as the contact name, and no global people search is provided. Only after explicit acceptance can confirmed friends view deliberately shared dive summaries containing date, title, site and optional selected coordinates. Private notes, equipment and certification files are not shared. Requests, decisions, blocks and technical operation results are stored under the account to support reliable retries (Article 6(1)(b) GDPR). Sharing may be withdrawn and friendships removed or blocked. Relationships and operation history remain until account deletion or documented cleanup. Stored feed views expire after one hour and are cleaned up when another view is requested. This feature does not email contacts.
10. Personal map records
A connected client can synchronise personal dive sites and coordinates, site assignments, species sightings with notes and source references, and buddy names and explicitly linked friend identifiers with its own account. These records follow the logbook rules for change history, export and backups. Map synchronisation does not publish dives or send friendship requests. Removing a friendship later does not erase historical buddy records already stored. Public area packages and public site search contain separate catalogue information; retrieving them does not create a personal visit.
11. Appearance and external content
Fonts, logos, styles and scripts are served from our own web server. No analytics, advertising, map, video or social-media services are embedded. If you explicitly choose an appearance, only the light or dark value is stored in browser session storage. This retains your choice across pages in the same tab; storage is discarded when the session ends. Selecting System removes the value. Storage serves the appearance you requested (Section 25(2)(2) TDDDG). External links connect to their provider only when clicked.
12. Email contact
Contact links open your email application. This website does not send emails and has no contact form. If you email us, we process your address, message and voluntary information to handle the enquiry, based on Article 6(1)(b) or (f) GDPR as applicable. Enquiries are retained only as needed for handling or legal obligations. Please do not send passwords, medical records or complete private logbooks.
13. Your rights
Subject to the applicable legal conditions, you have rights of access, rectification, erasure, restriction, portability and objection. Where processing relies on consent, you may withdraw it for the future. You may also complain to a data protection authority. Please use the contact above for requests.